| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138 |
- <?php
- // Configuration file for the webshop
- // Site settings
- define('SITE_NAME', 'Feuerwehr Freising Test Shop');
- define('SITE_URL', '/shop'); // Leave empty for relative URLs
- // Disclaimer (placeholder text shown on start page)
- define('DISCLAIMER_LINES', [
- 'Dieser Shop ist ein internes System für Mitglieder der Freiwilligen Feuerwehr Freising.',
- 'Diese Produkte können nicht von externen Personen bestellt werden.',
- ]);
- // Admin settings
- // Default password: admin123
- // Change these hashes after first login!
- //
- // To generate a new password hash in bash (using Python bcrypt):
- // python3 -c "import bcrypt; print(bcrypt.hashpw(b'your_new_password', bcrypt.gensalt(rounds=10, prefix=b'2y')).decode())"
- //
- // Alternative using htpasswd (if Apache tools are installed):
- // htpasswd -bnBC 10 "" your_new_password | sed 's/^://' | sed 's/\$2y\$/\$2y\$/'
- //
- // To add a new admin user:
- // 1) Create a new hash for the password (see commands above).
- // 2) Add a new entry to ADMIN_USERS: 'username' => 'hash'
- //
- // Note:
- // Runtime login source of truth is data/admins.json.
- // ADMIN_USERS is kept only as optional legacy reference.
- //
- // Example:
- // 'max' => '$2y$10$your_hash_here'
- //
- define('ADMIN_USERS', [
- 'admin' => '$2y$10$gArNDW.HhPmDcwYJ/xWRiOPkNop3695UIYzkV.G8WHQRUtLJVPLhy',
- 'manager' => '$2y$10$gArNDW.HhPmDcwYJ/xWRiOPkNop3695UIYzkV.G8WHQRUtLJVPLhy'
- ]);
- // Reservation settings
- define('RESERVATION_EXPIRY_DAYS', 60);
- define('ORDER_PREFIX', 'FWFS'); // Prefix for order number pattern: PREFIX-YEAR-SEQ
- // Browser-linked order history settings (no login required)
- define('ORDER_HISTORY_COOKIE_NAME', 'fw_shop_order_history');
- define('ORDER_HISTORY_COOKIE_TTL_DAYS', 365);
- define('ORDER_HISTORY_MAX_IDS', 10);
- define('ORDER_HISTORY_COOKIE_SECRET', 'change-this-order-history-secret'); // Change this to a long random secret
- // Email settings
- define('ADMIN_EMAIL', 'inbox@medowar.de'); // Fallback recipient if no admin account emails are configured
- define('FROM_EMAIL', 'shop@med0.de'); // Change to your sender email
- define('FROM_NAME', SITE_NAME);
- // Data file paths
- define('DATA_DIR', __DIR__ . '/data/');
- define('PRODUCTS_FILE', DATA_DIR . 'products.json');
- define('RESERVATIONS_FILE', DATA_DIR . 'reservations.json');
- define('ADMINS_FILE', DATA_DIR . 'admins.json');
- define('CATEGORIES_FILE', DATA_DIR . 'categories.json');
- define('FAQ_FILE', DATA_DIR . 'faq.json');
- // Backup and update client (Manage server)
- // -----------------------------------------------------------------------------
- // Connection. Instance and token come from the Manage server when the instance
- // is created there; the token is displayed exactly once. Leaving any of the
- // three empty disables backup upload, update check and heartbeat - the settings
- // page then says so instead of failing.
- define('MANAGE_SERVER_URL', 'https://manage.example.org'); // no trailing slash, no /api
- define('MANAGE_INSTANCE', '');
- define('MANAGE_TOKEN', '');
- // Seconds per HTTP request. Package download and backup upload use the long one.
- define('MANAGE_HTTP_TIMEOUT', 15);
- define('MANAGE_HTTP_TIMEOUT_LONG', 300);
- // Where the installed version lives. Never written by the client - it changes
- // when a release is rolled out over the installation.
- define('MANAGE_APP_ROOT', __DIR__);
- define('MANAGE_VERSION_FILE', __DIR__ . '/includes/version.php');
- define('MANAGE_VERSION_CONSTANT', 'APP_VERSION');
- // Working directories. Must be writable by PHP and must not be web-readable;
- // the root .htaccess denies all of data/.
- define('MANAGE_DIR', DATA_DIR . 'manage/');
- define('MANAGE_BACKUP_DIR', MANAGE_DIR . 'backups/'); // local archives
- define('MANAGE_WORK_DIR', MANAGE_DIR . 'work/'); // update staging, cleared after each run
- define('MANAGE_UPDATE_BACKUP_DIR', MANAGE_DIR . 'updates/'); // files an update overwrote
- define('MANAGE_LOG_FILE', MANAGE_DIR . 'manage-client.log');
- define('MANAGE_HEARTBEAT_STATE', MANAGE_DIR . 'heartbeat.json');
- define('MANAGE_MIGRATIONS_STATE', MANAGE_DIR . 'migrations.json');
- define('MANAGE_MIGRATIONS_DIR', __DIR__ . '/migrations');
- // What goes into a backup archive, relative to MANAGE_APP_ROOT.
- // 'glob' => shell glob, non-recursive 'dir' => recursive 'file' => single file
- // 'as' => path prefix inside the ZIP
- // assets/images holds product images uploaded through the admin UI; they exist
- // nowhere else, so a data-only backup would not survive a restore.
- // config.php is deliberately absent: backups are downloadable by anyone with a
- // Manage server login, and this file holds secrets.
- define('MANAGE_BACKUP_SOURCES', [
- ['as' => 'data', 'glob' => 'data/*.json'],
- ['as' => 'assets/images', 'dir' => 'assets/images'],
- ]);
- // Local archives kept on the server (minimum 1). Retention on the Manage server
- // is configured there and is usually much higher.
- define('MANAGE_BACKUP_LOCAL_RETENTION', 4);
- // This host has no cron, so an automatic backup is triggered by the admin
- // dashboard once this many seconds have passed since the last one. 0 disables
- // it and leaves only the button on the settings page.
- define('MANAGE_BACKUP_AUTO_INTERVAL_SECONDS', 604800); // 7 days
- // Compress archive entries (needs zlib) and upload every new backup.
- define('MANAGE_BACKUP_COMPRESS', true);
- define('MANAGE_BACKUP_UPLOAD', true);
- // Paths an update must never overwrite. A trailing slash marks a directory.
- // assets/images is deliberately NOT protected: the updater only touches paths
- // contained in the release package, so uploaded images survive anyway, while a
- // release can still ship its own images.
- define('MANAGE_UPDATE_PROTECTED_PATHS', ['config.php', 'data/', '.git/']);
- // A release package must contain at least one of these, otherwise it is
- // rejected before a single file is copied.
- define('MANAGE_UPDATE_SANITY_PATHS', ['admin/index.php', 'includes/functions.php']);
- // Callback after a successful deployment; see includes/after-update.php.
- define('MANAGE_UPDATE_POST_HOOK', [
- 'file' => __DIR__ . '/includes/after-update.php',
- 'callback' => 'shopAfterUpdate',
- ]);
- // Session settings
- if (session_status() === PHP_SESSION_NONE) {
- session_start();
- }
|